The repository is small and does not identify the package in its name or README. It lacks a security policy, although the release includes a README, changelog, and release notes.
15%
Total Score
0
50
50
Packagist marks the entire package as abandoned and names hypejunction/hypeinvite as its replacement. This is a direct warning against taking a new dependency on this release.
The last release was published on August 30, 2016, and there have been no releases in the last 12 months. The package is nearly ten years old without current release activity.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with long-term abandonment rather than an actively maintained project.
The linked repository name does not match the package name and its README does not mention the package. That weakens confidence that the repository is clearly maintained as this package's source.
The linked repository is not marked archived, but its last push was on August 30, 2016. The unarchived status does not offset the observed lack of recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ~1.0 | — | — |
hypejunction/ui_tabs Version ~1.0 | — | — |
hypejunction/forms_api Version ~1.0 | — | — |
hypejunction/elgg_tokeninput Version ~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.